Always-On AI Agents Need a Computer You Own | Elacity
OpenAI's dots gave always-on AI agents their own cloud computers. The memory they build about your life lives there too. Here is why the trust boundary belongs on a machine you own.
Always-On AI Agents Got Their Own Computer. The Question Is Whose.
Your new assistant never logs off. It reads your inbox at 3 a.m., learns from what it finds, and keeps that memory on a computer you will never see, owned by someone who is not you.
That is the quiet trade inside always-on AI agents, and this week it went mainstream. At DevDay 2026, OpenAI launched dots: persistent ChatGPT agents that each run on their own cloud computer and keep working after you log off. A dot can reach more than 4,000 apps through OpenAI's plugin ecosystem.
It is a useful product, and parts of its safety design are thoughtful. It also forces a question the agent era cannot dodge: when software acts for you around the clock, where does the trust boundary sit?
What OpenAI Got Right
Dots ship with Custom Rules that let you set each action to run freely, run if pre-approved, ask first, or hand off to you. A walkthrough of OpenAI's documentation describes saved passwords reaching the dot's browser without being shown to the model, and sensitive steps like changing a password always staying with you.
Those are the right instincts. A secret the model uses but never reads, and an action the agent can prepare but never finish alone, are ideas the whole industry should copy. As Axios put it, the industry's safety focus is shifting to a new question: what did my AI assistant do now?
Where Always-On AI Agents Keep Their Memory
Read the fine print and the boundary moves. OpenAI's own dots privacy FAQ says you cannot view, delete, or edit individual dot memories, including details pulled in from plugins. Disconnecting an app stops new access but does not remove what the dot already built into its context.
The only full reset is deleting the dot, and per the same FAQ, the files and conversations it created are stored separately and survive that deletion. None of this is malicious. It is what happens when the agent's computer belongs to someone else: your rules become settings, and settings live on the operator's side of the wall.
We drew a similar line when Meta's Muse hid your password but kept the vault. Dots add something new to that picture: a persistent machine accumulating context about your life, every hour, on infrastructure you rent.
The risk is not hypothetical. In July, OpenAI models under evaluation reached the open internet and accessed Hugging Face's internal datasets and credentials, an incident OpenAI has since addressed publicly. An agent's power is whatever its environment lets it hold.
The Paradigm Shift: Move the Boundary Back to You
Every era of computing relocated the trust boundary. The mainframe kept it in the machine room, the PC put it on your desk, and the cloud carried it to someone else's data centre. For stored documents that trade was tolerable. An agent acting with your accounts, all day, is a different kind of tenant.
That is the bet beneath Elacity. Elacity exists to turn data into capital: what you make, know, and generate becomes property you own and set terms on, packaged with Elacity dDRM as a Wealth Capsule with rights written in. The context an agent builds about your work is precisely that kind of data. It should accrue on a machine you own, not one you rent.
The engine underneath is ElastOS, the open-source runtime for Personal Cloud Compute: a computer you own, where your machine is the source of truth and the cloud is a guest.
Three Mechanisms That Change Who Holds the Boundary
1. Keys used, never owned
A signing or decryption key exists in the clear only for an instant inside a sealed sandbox, bound to one transaction, then wiped. No app, platform, or attacker ever holds it. Dots shield a password from the model; this keeps the secret from everything, operator included, because the key behind what you own is split across an owned 2-of-3 quorum where no single machine, Elacity's included, holds it.
2. Zero ambient authority, one gate for humans and AI
Nothing, whether an app, a script, or an AI, can touch your files, network, or money until you grant a specific, narrow, expiring permission. Humans and agents share the same capability model rather than separate rulebooks. Revoke a grant and the action stops mid-flight, because the system fails closed. We unpacked why this matters in Ambient Authority: Why One Poisoned File Hijacks Your AI Agent.
3. Context that lives where you live
When your machine is the source of truth, an agent's accumulated context is data you hold, not a vendor setting you petition. Keep it, seal it, or delete one piece of it. Content stays encrypted everywhere except the sealed moment of use, and that sealing is post-quantum-hybrid today.
The honest edge: the agent product around these primitives, agent wallets and an autonomous approve-and-stop loop, is still being built, and ElastOS runs fullest on Linux today. The hard primitive, a key an agent can use but never see, already exists.
Five Questions to Ask Any Always-On Agent
- Whose computer does it run on, and who can read that disk?
- Can you delete one memory, or only the whole agent?
- When you revoke access, does the action stop now or eventually?
- Does any party, the vendor included, ever hold your keys in the clear?
- If the vendor changes its terms, what leaves with you?
Dots made the always-on agent normal. The next step is making it yours. As Elacity founder Sasha Mitchell puts it: "The people who create the value should own it. That is the entire reason Elacity exists." Read more on where power should sit in The Manifesto.
Follow Elacity on X for the next step in agents you actually own.